Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑91816) Risks Enterprise Endpoints

Foxit PDF Reader contains a use‑after‑free vulnerability (CVE‑2026‑91816) that allows remote code execution when a user opens a malicious PDF or visits a crafted page. The flaw scores 7.8 on CVSS, highlighting the urgency for patching across all affected installations.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑91816) Threatens Endpoint Security

What It Is — A use‑after‑free flaw in the AcroForm handling of Foxit PDF Reader allows a remote attacker to execute arbitrary code on the victim’s machine. The vulnerability is identified as CVE‑2026‑91816.

Exploitability — Requires user interaction (opening a malicious PDF or visiting a crafted page). CVSS 7.8 (High) with Network‑local vector, Low complexity, and Privilege‑None.

Affected Products — Foxit PDF Reader (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability management and timely patch deployment, a core control for maintaining a defensible audit trail.
  • Evidence of patch status can be captured and presented in a Trust Center, satisfying multiple framework requirements (e.g., NIST CSF Identify, ISO 27001 Asset Management).
  • Unpatched endpoints expose organizations to downstream data‑exfiltration risk, undermining supplier‑risk assurance and third‑party due‑diligence processes.

Recommended Actions

  • Deploy Foxit’s September 2026 security update to all PDF Reader installations immediately.
  • Verify patch compliance via automated asset inventory and endpoint monitoring.
  • Incorporate the vulnerability into your vulnerability‑management program and map it to the relevant control objective (e.g., “Maintain up‑to‑date software”).
  • Monitor logs for anomalous PDF processing activity that could indicate exploitation attempts.

Source: Zero Day Initiative Advisory – ZDI‑26‑744

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-744/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →